agents: pull the forge token from bao; drop tea-login
forge-token.nix fetches swarm/agents/<agent>/forge-token under the agent's own store identity into /run/hive-agent-forge-token/token, and re-fetches on a timer so a rotation lands. hive-forge, the git credential helper, hive-forge-notify, forge-avatar-sync and the web UI read that file first and fall back to <state>/forge-token. tea-login is deleted: it copied the token into ~/.config/tea, which docs/swarm/credentials.md forbids for a store secret. hive-forge covers the same verbs. swarmctl gains agent mint-forge-token. Refs #3782
This commit is contained in:
parent
52c8c0b0de
commit
dd32a395f7
16 changed files with 501 additions and 156 deletions
|
|
@ -642,7 +642,7 @@ const FORWARDED_VARS: &[&str] = &[
|
|||
/// Map of forwarded env var -> the agent option carrying the same value.
|
||||
///
|
||||
/// Both exist because they're consumed at different times: the option is baked
|
||||
/// into scripts at build time (tea-login bakes `FORGE_URL` from it), the env
|
||||
/// into scripts at build time (forge-avatar-sync bakes `FORGE_URL` from it), the env
|
||||
/// var is read at runtime. Setting only one leaves the other on its default,
|
||||
/// which is how a hive ends up with two disagreeing answers for one value.
|
||||
///
|
||||
|
|
@ -1242,7 +1242,7 @@ where
|
|||
# resolve the agent's durable state dir without hard-coding it.
|
||||
# `environment.variables` only writes /etc/environment (login
|
||||
# shells); `systemd.globalEnvironment` is the analogue for
|
||||
# systemd units so tea-login / forge-avatar-sync /
|
||||
# systemd units so forge-avatar-sync /
|
||||
# hive-matrix-daemon etc. can read `$HYPERHIVE_STATE_DIR`
|
||||
# without each service having to redeclare it.
|
||||
environment.variables = {
|
||||
|
|
@ -1259,7 +1259,7 @@ where
|
|||
// Forwarded vars (HIVE_FORGE_URL etc.) also go into globalEnvironment,
|
||||
// not just the harness service env below, so EVERY service + shell in
|
||||
// the container inherits them — crucially the bash-task runner (where
|
||||
// `hive-forge` + `git` actually run), plus the matrix daemon, tea-login
|
||||
// `hive-forge` + `git` actually run), plus the matrix daemon, forge-avatar-sync
|
||||
// and interactive shells. Scoped to the harness service alone they were
|
||||
// invisible to bash tasks: harmless in shared netns (the localhost
|
||||
// default works) but broken under isolation, where the in-cluster
|
||||
|
|
@ -2081,7 +2081,7 @@ mod tests {
|
|||
fn render_flake_sets_service_url_options_from_forwarded_env() {
|
||||
// The forwarded env vars must ALSO become option assignments, because
|
||||
// the two are consumed at different times: the option is baked into
|
||||
// scripts at build time (tea-login's FORGE_URL), the env var is read at
|
||||
// scripts at build time (forge-avatar-sync's FORGE_URL), the env var is read at
|
||||
// runtime. Emitting only the env var leaves the option on its default,
|
||||
// which is how a hive ends up with two disagreeing answers for the same
|
||||
// URL.
|
||||
|
|
|
|||
Loading…
Reference in a new issue